Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The CRA Deadline You Can't Ignore: What Every Company Needs to Fix Before September 2026

The EU Cyber Resilience Act (CRA) introduces a 24-hour reporting requirement for actively exploited vulnerabilities from September 11, 2026. For companies selling products with digital elements into the EU, meeting that deadline will require more than compliance documentation — it demands fast vulnerability identification, clear ownership, reliable SBOM visibility, and a remediation process that can move quickly.

Vulnerability Scanning Best Practices for 2026

Periodic vulnerability scans are no longer a reliable security program for hybrid environments. NIST's guidance treats scanning as a recurring, risk-based control that should account for changing vulnerabilities, historical results, authenticated coverage, and correlations between findings over time (NIST vulnerability-scanning guidance). Industry practice is moving in the same direction.

The Vulnerability Tax: What CVE Response Costs at the Network Edge

Network edge vulnerabilities are accelerating. Cato’s cloud-native architecture reduces customers’ attack surface and shortens exposure to emerging vulnerabilities. The Cato CVE Exposure Calculator shows what that difference could mean for your organization. Another Known Exploited Vulnerability (KEV). Another emergency CAB. Another weekend spent upgrading firmware. You have to respond. The question is how much each response costs the business.

Why Your AI Application Is Exposed

Imagine getting three separate security reports back for your new enterprise AI assistant: On paper, the application looks ready for production, but in reality, a threat actor bypasses your guardrails in minutes. How? By using the AI model as an intermediary. The attacker steers the LLM to invoke the internal utility tool, thereby bridging an untrusted prompt directly to the backend execution sink.

The skill layer is a dependency problem without a lockfile: what the OWASP Agentic Skills Top 10 gets right

OWASP published version 1.0 of the Agentic Skills Top 10 on August 17, defining ten risk classes for the layer where agents find, load, and run reusable instructions and code. This standard arrived while the problem was still forming, mapping directly to AISVS, the Agentic Security Initiative Top 10, the MCP Top 10, ISO/IEC 42001, and the NIST AI RMF. It ships with working code for signing, sandboxing, and pinning.

CISO Risk Intel Brief: Five-Day Exploit Windows, 72-Hour KEV Clocks, and the September Regulatory Squeeze

This executive intelligence briefing covers from the past week (19-26 August 2026) and the past month (approximately 27 July–26 August 2026). Exploit velocity has overtaken patch cadence as the binding constraint. VMware vCenter moved from Broadcom patch to mass exploitation in five days, and this week’s CISA KEV due dates are measured in 72 hours, not 30 days.